CHIEF Information Security Officer
$147.5k - $211kNew York Life
Location Designation: Hybrid - 3 days per week Role Overview Lead the strategy, governance, operating model, and execution oversight for Enterprise Vulnerability Management across infrastructure, cloud, endpoints, and application‑dependent services. This role creates a centralized function that turns scan findings into measurable risk reduction by aligning asset visibility, risk‑based prioritization, patching discipline, remediation orchestration, and executive accountability. You will own accountability for vulnerability remediation performance across the enterprise. Success depends on strong partnership with platform, application, security, and risk teams, backed by senior leadership endorsement that gives the role authority to drive remediation actions, enforce SLA discipline, and escalate unmanaged risk. What You’ll Do Strategy, Governance & Operating Model Own the enterprise vulnerability remediation strategy and roadmap across on‑prem, cloud, and SaaS environments. Define and enforce standards, policies, and controls for scanning, triage, remediation SLAs, and exception handling. Chair or co‑chair governance forums covering vulnerability risk, remediation progress, and chronic issues with Infra, App, Security, and Risk leaders. Design a centralized operating model that integrates scanning, triage, remediation execution, change coordination, and executive reporting. Enterprise Platform Ownership Serve as executive product owner for vulnerability management platforms (network and host scanners, container and cloud posture tools, application security integrations). Define platform roadmaps, integration priorities (CMDB, asset inventory, ITSM, SIEM, GRC), and data quality objectives. Ensure platforms are reliable, scalable, and easy for engineering teams to consume (dashboards, APIs, reports). Asset, Exposure & Risk Prioritization Partner with CMDB, asset management, and cloud teams to maintain accurate, in‑scope inventories tied to business services and criticality. Implement risk‑based prioritization that accounts for exploitability, business impact, exposure, compensating controls, and critical asset classes such as internet‑facing and crown‑jewel systems. Standardize risk scoring and rapid treatment paths for KEVs, zero‑days, high‑risk misconfigurations, and systemic control failures. Remediation Orchestration & Integration with IT Operations Align vulnerability remediation with patching, configuration management, and change processes in IT Operations. Define and track remediation SLAs for different classes of vulnerabilities and assets; drive accountability with platform and app owners. Partner with AIOps/Automation teams to implement automated fixes and workflow orchestration where safe and appropriate. Cloud, Container & Application Security Alignment Integrate vulnerability management with cloud security posture management (CSPM), container scanning, and application security pipelines (SAST/DAST/Software Composition Analysis). Ensure DevOps/SRE teams receive actionable, contextualized findings early in the lifecycle. Help define secure baselines, golden images, and hardened configurations that reduce recurring vulnerabilities. Metrics, Reporting & Executive Communication Define and manage key performance indicators and risk metrics (e.g., mean time to remediate by severity, SLA adherence, exposure windows, vulnerability density on critical assets). Produce regular reporting and dashboards for Technology leadership, the CISO organization, Risk, and regulators/internal audit as needed. Translate technical risk into business impact and clear remediation priorities for senior stakeholders. Incident & Crisis Support Support Security and Incident Response teams during high‑severity events (zero‑days, active exploits) with rapid asset scoping, prioritization, and remediation coordination. Ensure lessons learned from incidents are codified into playbooks, standards, and automation. Leadership, People & Culture Lead and develop a team of vulnerability management engineers, analysts, and program managers. Foster a culture of “secure‑by‑default” and shared responsibility for vulnerability remediation across Infra, App, and Operations teams. Provide coaching, training, and clear guidance to engineering teams on patching practices, exception handling, and secure configurations. Authority and Scope This role requires explicit senior leadership endorsement to operate effectively across organizational boundaries. The role holder is empowered to: Set enterprise remediation expectations, standards, and SLA timelines. Require remediation plans and target dates from infrastructure and application teams. Escalate missed deadlines, unresolved blockers, and unmanaged risk through formal governance channels. Challenge unsupported exception requests and ensure risk acceptance is documented, time‑bound, and approved at the right level. Coordinate end‑to‑end remediation activity spanning endpoints, servers, cloud, middleware, containers, and application‑dependent services. Success Measures & Key Outcomes (First 6–12 Months) Visibility & Data Quality – High‑confidence coverage of in‑scope assets (servers, endpoints, cloud workloads, containers, critical apps) with regular scanning cycles. SLA adherence – Critical and high vulnerabilities remediated within target windows across endpoint, server, cloud, and application‑dependent environments. Risk reduction – Reduction in aging critical findings, repeat exposure on tier‑1 assets, and exception backlog. Operational integration – Patching and remediation embedded into change and maintenance processes with clear ownership and workflow evidence. Executive visibility – Dashboards and governance reporting routinely used by Technology, Security, Risk, and Audit leadership. Control maturity – Improved audit outcomes, stronger evidence quality, and reduced recurrence of remediation process gaps. Reporting & Assurance – Executive dashboards and metrics in place, used routinely by Technology and Security leadership. Positive feedback from Internal Audit/Compliance on evidence quality, coverage, and remediation discipline. What You’ll Bring 12–15+ years of experience in Infrastructure/IT Operations, Security Engineering, or SRE, with 5+ years in senior leadership roles owning vulnerability management and/or patching at enterprise scale. Deep understanding of enterprise infrastructure and platforms: Windows/Linux, databases, network devices, endpoints, cloud (AWS/Azure/GCP), and Kubernetes or containerized workloads. Hands‑on familiarity with vulnerability management tooling, such as Tenable, Qualys, Rapid7, cloud‑native security services, and container/image scanning platforms. Strong experience integrating vulnerability platforms with ITSM/CMDB, asset management, SIEM, and GRC tools. Proven track record building and running risk‑based remediation programs with clear SLAs, metrics, and reporting to senior leadership. Solid knowledge of security frameworks and regulatory requirements, such as NIST CSF, CIS controls, SOX, NYDFS, PCI, or similar. Strong understanding of change, patch, and configuration management in large IT Operations environments. Demonstrated ability to influence senior stakeholders, negotiate priorities, and drive decisions across Technology, Security, and Business teams. Excellent communication, storytelling, and presentation skills—able to convey complex technical risk in clear business terms. Nice to Have Experience in financial services or other highly regulated industries. Background with application security (SAST/DAST/SCA), CSPM, and container security; experience embedding security into CI/CD. Relevant certifications: CISSP, CISM, CRISC, cloud security certs (e.g., CCSP), or ITIL/SRE credentials. Working Model Hybrid role based in New York, NY with regular in‑person collaboration for governance forums, planning sessions, and key events. Occasional off‑hours engagement may be required during critical security events or major remediation campaigns. You’ll operate at the intersection of IT Operations and Cybersecurity to reduce risk while enabling reliable, modern platforms for the business. Pay Transparency Salary Range: $147,500 – $211,000 Overtime eligible: Exempt Discretionary bonus eligible: Yes Sales bonus eligible: No Actual base salary will be determined based on several factors but not limited to individual’s experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program. #J-18808-Ljbffr
$300k - $350k
...decided to fix it. National security professionals, journalists, parents... ...of their most personal information. The Team At Cape, we are the... ...Mission) The CISO is our chief protector. Our infrastructure... ...is based out of our NYC or DC office and reports to our founder and...SuggestedOdd jobFull timeWork at officeImmediate startRelocation package$125k - $150k
Job Description The Department of Records and Information Services is seeking to hire a Computer Systems Manager Non-Manager to serve as the Chief Information Security Officer (CISO). The Computer Systems Manager-Non-Manager will be responsible for compliance with the...SuggestedPermanent employmentFull timeWork at officeShift workWeekend workAfternoon shift- ...reliable, backed by our Proof of Reserves. Across our multiple offices globally, we are united by our core principles: We Before Me, Do... ...every OK-er. About the opportunity We're looking for a security leader for the Americas who's equally comfortable in front of a...Suggested
$300k - $375k
...regulatory compliance in everything we do. Join us and help build the future of global investing! About the Role As Chief Information Security Officer, you will be responsible for leading and strengthening the company’s entire security function across four key domains...SuggestedFull timeWork at officeWorldwide$350k - $400k
...service to seller and buyer clients. Role Executive Summary Compass International Holdings is seeking a seasoned Chief Information Security Officer to own and evolve the enterprise security program. This is an executive & highly technical role at the...SuggestedFlexible hours$350k - $400k
...Group Chief Information Security Officer The Chief Information Security Officer (CISO) will lead and oversee the Information Security program across the entire organization. The role will be responsible for developing, implementing, and maintaining a unified enterprise...Contract workLocal areaShift work- ...Responsibilities Establish and execute an enterprise information security strategy and operating model aligned with business objectives and risk appetite. Continuously assess and strengthen Genworth’s cyber and technology risk posture in support of enterprise resilience...Contract workTemporary work
- ...Who are we? Cohere is the leading security-first enterprise AI company. We build cutting... ...in Toronto and San Francisco, with key offices in London, New York City, Montreal,... ...us! The Opportunity Cohere seeks a Chief Information Security Officer who can help shape Cohere...Full timeWork at officeLocal areaRemote workHome office
$65k - $150k
...Overview This incumbent will provide Strategy, Programs, Governance, Risk and Compliance functions as required to fulfill BOCNY information security program requirements. This incumbent will provide Strategy Coordination, CISO Projects Management, Training & Culture,...Work experience placement$350k - $400k
Job Summary The Chief Information Security Officer (CISO) will lead and oversee the Information Security program across the entire organization. The role will be responsible for developing, implementing, and maintaining a unified enterprise security strategy that ensures...Full timeContract work- ...CAIS is seeking a Chief Information Security Officer (CISO) who pairs deep technical expertise with strategic vision to lead the firm’s cybersecurity program and Operational Risk Management practices This role will drive security strategy—including AI security strategy...Work at officeFlexible hours
- ...Chief Information Security Officer (CISO) US or Canada Location: Remote (U.S. or Canada) Type: US Applicants – Full‑Time; Canadian Applicants – Independent Contractor About Human Agency We’re scaling rapidly and have a growing pipeline of opportunities that demand exceptional...Full timeContract workFor contractorsFor subcontractorWork at officeRemote workDay shift
- ...messaging across presentations, graphs, and narratives, and to build a roadmap for enterprise awareness. In this role you will lead cross‑functional collaboration, drive change communications for security initiatives, manage stakeholder feedback, and #J-18808-Ljbffr...
- ...Chief Information Security Officer (CISO) About the Company Innovative online real estate platform Industry Real Estate Type Privately Held, VC-backed Founded 2012 Employees 1001-5000 Funding $200+ million Categories...Local area
- ...Chief Information Security Officer (CISO) About the Company Established data management and secure communications firm serving highly regulated industries. Industry Information Technology and Services Type Privately Held About the Role The Company...
- ...Chief Information Security Officer (CISO) About the Company Trusted provider & publisher of consumer insights about car models & auto brands Industry Market Research Type Privately Held, Private Equity-backed Founded 1968 Employees 1001-5000...
- CHIEF INFORMATION SECURITY OFFICER THE POSITION IN A NUTSHELL Sciens is seeking a Chief Information Security Officer (CISO), who will be responsible for establishing and operating a right‑sized, risk‑based cybersecurity program that protects the company, supports growth...Temporary workWork experience placement
$300k - $375k
Chief Information Security Officer Location: New York, NY (Hybrid) Pay Range: $300,000 USD - $375,000 USD About The Role As Chief Information Security Officer, you will lead and strengthen the company’s entire security function across Governance, Risk & Compliance (GRC...Visa sponsorship$150k
...Overview Our top-notch Information Security team quickly finds and responds to real time threats. These critical thinkers have... ...in this growing and ever-changing field. The Deputy Chief Information Security Officer (Deputy CISO) serves as the principal lead to the CISO...Work at officeImmediate startRemote workFlexible hours$350k - $375k
...About the role InvestCloud is seeking an experienced Chief Product & Information Security Officer (CPISO) to lead the company's global information security strategy, governance, risk management, and incident response capabilities. Uniquely, this role carries explicit...Full timePart timeFlexible hours- ...Advisor & Field CTO for Trusted Services to join their Platform Specialist team in New York. This senior role will engage with C-suite security leaders to articulate Salesforce's security posture and accelerate trust in their solutions. Responsibilities include developing...
- ...visit healthsolutions.org. Position Summary The Chief Technology and Information Officer (CTIO) is an executive leader responsible for advancing... ...data infrastructure, cybersecurity, HIPAA and NYS OHIP security compliance, interoperability, AI governance, analytics...Monday to Friday
- ...Chief Information Officer / Chief Technology Officer (CIO / CTO) job at Delan Associates, Inc. New York, NY. Now Hiring: Chief Information... ...in advancing the organization's mission, efficiency, and security. What You’ll Do Develop and execute a comprehensive...Permanent employmentImmediate start
$120k - $200k
...Information System Security Officer (ISSO) Employment Type: Full-Time, Mid-Level Department: Administrative and Logistics Support As a FSR ISSO, you will be embedded on-site with U.S. Government customers to ensure the secure, compliant operation of a...Full timeFlexible hours$125k - $150k
...with external partners - City Hall and the Office of Mass Engagement (to whom PEU reports)... ...Management Planning M1 to function as a Chief Strategy Officer who can help PEU stand... ...as described in "1" above. Additional Information The City of New York is an inclusive...Full timeWork at officeMonday to FridayFlexible hoursShift work- ...Life Plan Community. by Foulkeways on July 15, 2026 Director of Information Technology (IT) (1) Full time position to provide strategic... ...efficiency, support resident care and services, and ensure the security and reliability of all information systems. Job Category: Administration...Full time
$250.44k - $375.67k
...Proof of Reserves. Across our multiple offices globally, we are united by our core principles... ...the opportunity We're looking for a security leader for the Americas who's equally... ...regardless of race, color, genetic information, creed, religion, sex, sexual orientation...Full time- ...building a smarter, faster, and more secure financial future by revolutionizing... ...About the team The Security & Information Technology organization is the backbone... ...Reporting directly to the Global CTO, the Chief Information Security Officer (CISO) & Head of Information...Full timeContract workTemporary workWork at officeWorldwideHome officeFlexible hours
- Salesforce, Inc. is seeking a CISO Advisor & Field CTO for Trusted Services to bridge their security capabilities with the CISO community. You will engage at the executive level, addressing key enterprise security challenges and driving trust in Salesforce's solutions....
$208.18k - $278.46k
salesforce.com, inc. is seeking a CISO Advisor & Field CTO for Trusted Services to engage with executive-level security leaders. This role emphasizes cybersecurity strategy, requires 15+ years of experience, and involves crafting security frameworks to enhance trusted...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to CHIEF Information Security Officer. Be the first to apply!
- information security officer New York, NY
- business information security officer New York, NY
- information security officer iso New York, NY
- ciso New York, NY
- chief information security officer New York, NY
- chief information security officer ciso New York, NY
- information security analyst New York, NY
- information security compliance analyst New York, NY
- director information security New York, NY
- information security internship New York, NY




